Security
Denial of Service Prevention
469 Cisco 500 Series Stackable Managed Switch Administration Guide
21
• IP Address—Enter the IPv4 address for which the ICMP packet filtering is 
activated or select All Addresses to block ICMP packets from all source 
addresses. If you enter the IP address, enter either the mask or prefix length.
• Network Mask—Select the format for the subnet mask for the source IP 
address, and enter a value in one of the field:
- Mask—Select the subnet to which the source IP address belongs and 
enter the subnet mask in dotted decimal format.
- Prefix Length—Select the Prefix Length and enter the number of bits that 
comprise the source IP address prefix.
STEP  4 Click Apply. The ICMP filtering is defined, and the Running Configuration is 
updated.
IP Fragmented Filtering
The IP Fragmented page enables blocking fragmented IP packets.
To configure fragmented IP blocking:
STEP 1 Click Security > Denial of Service Prevention > IP Fragments Filtering.
STEP  2 Click Add.
STEP  3 Enter the parameters.
• Interface—Select the interface on which the IP fragmentation is being 
defined.
• IP Address—Enter an IP network from which the fragmented IP packets is 
filtered or select All Addresses to block IP fragmented packets from all 
addresses. If you enter the IP address, enter either the mask or prefix length.
• Network Mask—Select the format for the subnet mask for the source IP 
address, and enter a value in one of the field:
- Mask—Select the subnet to which the source IP address belongs and 
enter the subnet mask in dotted decimal format.
- Prefix Length—Select the Prefix Length and enter the number of bits that 
comprise the source IP address prefix.